{
  "threat_severity" : "Moderate",
  "public_date" : "2023-01-16T00:00:00Z",
  "bugzilla" : {
    "description" : "satellite: Blind SSRF via Referer header",
    "id" : "2145254",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2145254"
  },
  "cvss3" : {
    "cvss3_base_score" : "3.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-918",
  "details" : [ "A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server.", "A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server." ],
  "acknowledgement" : "This issue was discovered by Fernando Velazquez (Red Hat).",
  "affected_release" : [ {
    "product_name" : "Red Hat Satellite 6.13 for RHEL 8",
    "release_date" : "2024-02-29T00:00:00Z",
    "advisory" : "RHSA-2024:1061",
    "cpe" : "cpe:/a:redhat:satellite:6.13::el8",
    "package" : "foreman-0:3.5.1.24-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.13 for RHEL 8",
    "release_date" : "2024-02-29T00:00:00Z",
    "advisory" : "RHSA-2024:1061",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.13::el8",
    "package" : "foreman-0:3.5.1.24-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.13 for RHEL 8",
    "release_date" : "2024-02-29T00:00:00Z",
    "advisory" : "RHSA-2024:1061",
    "cpe" : "cpe:/a:redhat:satellite_utils:6.13::el8",
    "package" : "foreman-0:3.5.1.24-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.14 for RHEL 8",
    "release_date" : "2023-11-08T00:00:00Z",
    "advisory" : "RHSA-2023:6818",
    "cpe" : "cpe:/a:redhat:satellite:6.14::el8",
    "package" : "foreman-0:3.7.0.9-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.14 for RHEL 8",
    "release_date" : "2023-11-08T00:00:00Z",
    "advisory" : "RHSA-2023:6818",
    "cpe" : "cpe:/a:redhat:satellite_capsule:6.14::el8",
    "package" : "foreman-0:3.7.0.9-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.14 for RHEL 8",
    "release_date" : "2023-11-08T00:00:00Z",
    "advisory" : "RHSA-2023:6818",
    "cpe" : "cpe:/a:redhat:satellite_utils:6.14::el8",
    "package" : "foreman-0:3.7.0.9-1.el8sat"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2022-4130\nhttps://nvd.nist.gov/vuln/detail/CVE-2022-4130" ],
  "name" : "CVE-2022-4130",
  "csaw" : false
}